bug-bounty

Orchestrate bug bounty workflows with impact validation and CVSS 3.1 scoring.

1.1k|191|Updated Jun 24, 2026
One-click install
npx skills add https://github.com/uphiago/recon-skills --skill bug-bounty-uphiago
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bug-bounty
Source: https://github.com/uphiago/recon-skills/tree/main/redteam/bug-bounty
Command: npx skills add https://github.com/uphiago/recon-skills --skill bug-bounty-uphiago

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Bug bounty hunting is often disorganized, with researchers wasting hours on theoretical bugs, shallow reconnaissance, or low-impact findings that never qualify for a payout. This skill eliminates that wasted effort by providing a strict, impact-first workflow that filters out non-exploitable issues immediately and focuses on high-severity, chainable vulnerabilities that deliver real value to programs.

Core Features & Use Cases

  • Full End-to-End Pipeline: Covers every phase of bug bounty work from initial target recon and pre-hunt intelligence gathering to vulnerability hunting across 30+ classes, A-to-B attack chaining, and professional report writing with CVSS 3.1 scoring.
  • Impact-First Guardrails: Includes a 7-question gate to kill weak findings fast, rules to avoid theoretical bugs, and a 5-minute/one-hour rule to prevent time wasted on dead-end targets.
  • Use Case: For a new bug bounty target, use this skill to run a structured recon pipeline, identify crown jewel assets, hunt for chained vulnerabilities like SSRF to cloud metadata exfiltration, and draft a professional, program-compliant report that maximizes payout potential.

Quick Start

Use this skill to conduct a complete authorized bug bounty assessment for a new target, from initial scope verification through validated high-impact vulnerability reporting.

Frequently Asked Questions about bug-bounty

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure bug bounty reconnaissance to find high-impact vulnerabilities instead of low-severity bugs?

Bug bounty reconnaissance requires an impact-first workflow that eliminates theoretical findings early. By applying a 7-question validation gate, you identify crown jewel assets and avoid dead-end targets before wasting effort on non-exploitable vulnerabilities.

What is the A-to-B attack chaining methodology in vulnerability hunting?

A-to-B attack chaining is a vulnerability hunting methodology that links individual low-severity bugs into a critical exploit path. An example is chaining an SSRF vulnerability to cloud metadata exfiltration, turning isolated findings into high-severity reports that deliver real value to bug bounty programs.

How do I write a professional bug bounty report with CVSS 3.1 scoring?

Professional bug bounty report writing uses a human-tone template generation process that incorporates CVSS 3.1 scoring. This ensures your vulnerability report is program-compliant, clearly communicates impact, and maximizes payout potential for validated high-severity findings.

Can I use this workflow for AI and LLM security testing in bug bounty programs?

Yes, the bug bounty workflow covers AI and LLM feature testing alongside 30+ other vulnerability classes. It applies the same structured reconnaissance and impact validation to identify and report exploitable security issues in AI-integrated application features.

What is the best way to stop wasting time on dead-end bug bounty targets?

The best way to avoid dead-end bug bounty targets is applying a 5-minute/one-hour rule alongside an impact-first guardrail. This strict time management prevents wasted effort on theoretical bugs by forcing you to validate exploitability and severity before deeper reconnaissance.